Field
Description
•
3DES
(default value): 3DES is an extension of the DES al-
gorithm with an effective key length of 112 bits, which is rated
as secure. It is the slowest algorithm currently supported.
•
Twofish
: Twofish was a final candidate for the AES
(Advanced Encryption Standard). It is rated as just as secure
as Rijndael (AES), but is slower.
•
Blowfish
: Blowfish is a very secure and fast algorithm.
Twofish can be regarded as the successor to Blowfish.
•
CAST
: CAST is also a very secure algorithm, marginally
slower than Blowfish, but faster than 3DES.
•
DES
: DES is an older encryption algorithm, which is rated as
weak due to its small effective length of 56 bits.
•
AES
: Rijndael has been nominated as AES due to its fast key
setup, low memory requirements, high level of security
against attacks and general speed.
•
AES-128
: Rijndael has been nominated as AES due to its
fast key setup, low memory requirements, high level of secur-
ity against attacks and general speed. Here, it is used with a
key length of 128 bits.
•
AES-192
: Rijndael has been nominated as AES due to its
fast key setup, low memory requirements, high level of secur-
ity against attacks and general speed. Here, it is used with a
key length of 192 bits.
•
AES-256
: Rijndael has been nominated as AES due to its
fast key setup, low memory requirements, high level of secur-
ity against attacks and general speed. Here, it is used with a
key length of 256 bits.
Hash algorithms (Authentication):
•
MD5
(default value): MD 5 (Message Digest #5) is an older
hash algorithm. It is used with a 96 bit digest length for IPSec.
•
SHA1
: SHA1 (Secure Hash Algorithm #1) is a hash algorithm
developed by the NSA (United States National Security Asso-
ciation). It is rated as secure, but is slower than MD5. It is
used with a 96 bit digest length for IPSec.
•
RipeMD 160
: RipeMD 160 is a 160 bit hash algorithm. It is
used as a secure replacement for MD5 and RipeMD.
•
Tiger192
: Tiger 192 is a relatively new and very fast al-
gorithm.
11 VPN
Funkwerk Enterprise Communications GmbH
324
bintec R1xxx/R3xxx/R4xxx